CVE-1999-1182Improper Restriction of Operations within the Bounds of a Memory Buffer in Linux

3 documents3 sources
Severity
7.2HIGHNVD
EPSS
0.1%
top 78.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 17
Latest updateApr 30

Description

Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local users to gain privileges by calling a setuid program with a long program name (argv[0]) and forcing ld.so/ld-linux.so to report an error.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages5 packages

NVDredhat/linux4.0, 4.1, 4.2+2
NVDdelix/dld5.2

Also affects: Debian Linux 4.0

🔴Vulnerability Details

2
GHSA
GHSA-h7jj-55g9-vf43: Buffer overflow in run-time linkers (1) ld2022-04-30
CVEList
CVE-1999-1182: Buffer overflow in run-time linkers (1) ld2001-09-12
CVE-1999-1182 — Debian Linux vulnerability | cvebase